Vulnerabilities > Usermin
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2003-03-03 | CVE-2003-0101 | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges. | 10.0 |
2002-08-12 | CVE-2002-0757 | Authentication Bypass vulnerability in Webmin / Usermin (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations. | 7.5 |
2002-08-12 | CVE-2002-0756 | Cross-Site Scripting vulnerability in Webmin / Usermin Login Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies. | 7.5 |